×

Loading...
Ad by
  • 推荐 OXIO 加拿大高速网络,最低月费仅$40. 使用推荐码 RCR37MB 可获得一个月的免费服务
Ad by
  • 推荐 OXIO 加拿大高速网络,最低月费仅$40. 使用推荐码 RCR37MB 可获得一个月的免费服务

If there's no mail.*, you might want to consider adding one, just for the sake of clearness. Those NXDOMAIN entries are from DNS server.

本文发表在 rolia.net 枫下论坛The netstat output you mentioned are from unix domain sockets, what we need is internet connections (should be the section above the unix domain one if you use 'netstat -an'). According to your telnet result, there should be one listenning on tcp/110 at least.

You telnet to tcp/25 failed, meaning that no smtp server is running. Because qmail's smtpd and pop3d are running out of tcpserver (an inetd replacement), you can do 'ps ax | grep tcpserver' to see how many of those are running. If you only get one entry, that means only one of smtpd and pop3d is running, most likely it would be the pop3d one. If so, you can try to go to /etc/rc.d/init.d (I'd assume you use redhat? a 'uname -a' will tell) and see if there's file called qmail, smtpd or the like, then do a './<filename> start'.

Also, is this server a DNS server too? If so, and since this server was setup 2 years ago, the DNS server may be vulnerable to attacks.

Unfortunately I didn't receive your email. You can send to me directly at ddai55@yahoo.com.更多精彩文章及讨论,请光临枫下论坛 rolia.net
Report

Replies, comments and Discussions:

  • 枫下家园 / 电脑用户 / help!!, Dessnis, 阿土,暴力大熊猫.. 各位兄弟, I tried the way you teached me on the mail server, problem is still there, next is some information:
    本文发表在 rolia.net 枫下论坛1. ps ax | grep sendmail
    10811 2 s 0:00 grep sendmail

    2. ps ax | grep pop
    10823 2 s 0:00 grep pop

    3. ps ax | grep splogger,
    it works, then I found some file under var/log, "all", "debug", "xferlog"
    "all" is very long

    "debug" :
    Mar 1 14:40:02 mail kernel: VFS : Disk change detected on device fd(2,0)
    ..(repeated)
    Mar 1 14:50:20 mail kernel: VFS : Disk change detedted on device fd(2,1)
    ..(repeated)

    "xferlog":
    Wed Mar 6 00:21:59 2002 CPE0080CE95B9F.cpe.net.cable.rogers.com 573 /home/ftp/etc/passwd a _ 0 a guest ftp 0*c

    I think maybe this cause the problem from Thursday.

    4. Also, I checked the supervise and multilog, the supervise doesn't work but multilog works. I can't find those directories you mentioned. There's no lsof installed on mail server.

    Then, I have these information, how can I deal with the problem?

    I checked the inetd.conf, try the "kill" command under the instruction of that config file, but no use.
    kill -HUP 88
    88 is the pid of inetd

    Another question, how can I copy file to floppy, I tried "mount", but not works. :(..

    Sorry to trouble you.更多精彩文章及讨论,请光临枫下论坛 rolia.net
    • 你不是用的 qmail 吗?当然差不到 sendmail 的信息。试试 ps ax|grep qmail-pop3d ,如果有就杀掉重起,如果没有就运行一下
    • Come in please.
      本文发表在 rolia.net 枫下论坛1. You found out that your mail system is using splogger, so the log is done through syslog. Take a look at your /etc/syslog.conf file, there should be an entry beginning with mail.*, and the file on the right hand side of that line is the mail log file. Take a look at that file. If there's no mail.* line, you best bet is the All file.

      2. About the log files you mentioned: All could be a catch-all log file, that's why it's very long; Debug could be the file for debug information, not necessary for your mail system (from the entries you post, those are from kernel); xferlog is the log file for ftp, thus irrelevant.

      3. To find out if your mail server is running, do a 'netstat -ln' and see if there's anything listening on tcp/25 (smtp) and tcp/110 (pop3). lsof is to find out which process is listening on those ports, which is not available to netstat.

      4. To mount the floppy, you'll need to know which fs your floppy disk was formatted to. If it's fat, use 'mount -t msdos /dev/fd0 /mnt'. If it's ext2, use 'mount -t ext2 /dev/fd0 /mnt'. Also if you have mtools installed, you don't need to mount the floppy if the disk is fat, just use mdir, mcopy, etc. as if it's in msdos.更多精彩文章及讨论,请光临枫下论坛 rolia.net
      • thanks again, In syslog.conf, there is no mail.*, but *.* conntect to All file, so All is the log file, in "All" file, I noticed a lot of info like: sysqurey: findns error NXDOMAIN...
        I can ping our mail server, telnet mail.xxxx.com 110 also success, but telnet mail.xxxx.com 25 failed.

        about netstat, -l not reply, I use netstat -an, there are two listening: 108 -- /var/run/ ndc, another is 39 --/dev/log,

        Dennis, I send u an email through rolia the day before, did you receive it?
        • If there's no mail.*, you might want to consider adding one, just for the sake of clearness. Those NXDOMAIN entries are from DNS server.
          本文发表在 rolia.net 枫下论坛The netstat output you mentioned are from unix domain sockets, what we need is internet connections (should be the section above the unix domain one if you use 'netstat -an'). According to your telnet result, there should be one listenning on tcp/110 at least.

          You telnet to tcp/25 failed, meaning that no smtp server is running. Because qmail's smtpd and pop3d are running out of tcpserver (an inetd replacement), you can do 'ps ax | grep tcpserver' to see how many of those are running. If you only get one entry, that means only one of smtpd and pop3d is running, most likely it would be the pop3d one. If so, you can try to go to /etc/rc.d/init.d (I'd assume you use redhat? a 'uname -a' will tell) and see if there's file called qmail, smtpd or the like, then do a './<filename> start'.

          Also, is this server a DNS server too? If so, and since this server was setup 2 years ago, the DNS server may be vulnerable to attacks.

          Unfortunately I didn't receive your email. You can send to me directly at ddai55@yahoo.com.更多精彩文章及讨论,请光临枫下论坛 rolia.net